nerdexam
(ISC)2

CGRC · Question #314

The authorization approach that is employed when multiple organizational officials either from the same organization or different organizations, have a shared interest in authorizing an information…

The correct answer is A. Joint. A joint authorization approach is employed when multiple organizational officials, potentially from different entities, have a shared interest and responsibility in authorizing an information system.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

The authorization approach that is employed when multiple organizational officials either from the same organization or different organizations, have a shared interest in authorizing an information system. Response:

Options

  • AJoint
  • BSingle
  • CMingle
  • DDouble

How the community answered

(45 responses)
  • A
    89% (40)
  • B
    7% (3)
  • C
    2% (1)
  • D
    2% (1)

Why each option

A joint authorization approach is employed when multiple organizational officials, potentially from different entities, have a shared interest and responsibility in authorizing an information system.

AJointCorrect

Joint authorization specifically refers to a process where multiple authorizing officials, either from within one organization or across different organizations, collectively make a decision to authorize an information system. This approach is used when shared ownership, responsibility, or interest necessitates a collaborative authorization decision, ensuring all stakeholders' concerns are addressed.

BSingle

Single authorization involves only one authorizing official taking responsibility for the system's authorization.

CMingle

Mingle is not a recognized authorization approach within IT security frameworks.

DDouble

Double is not a recognized authorization approach within IT security frameworks.

Concept tested: Joint authorization approach

Source: https://csrc.nist.gov/glossary/term/joint-authorization

Topics

#Joint authorization#System authorization#Governance approach

Community Discussion

No community discussion yet for this question.

Full CGRC Practice